VORANT. Threat Intelligence Sign in Get the full feed

Cisco ASA, FTD firewalls exploited for persistent access

critical vulnerability infrastructuregovernment-nationalfinancial-servicestelecommunicationsenergy

Cisco ASA and FTD firewalls have critical vulnerabilities enabling remote code execution; active exploitation observed with persistent backdoor deployment.

The Japan Information-technology Promotion Agency (IPA) issued an alert regarding critical vulnerabilities affecting Cisco Secure Firewall ASA and Cisco Secure FTD products. The vulnerabilities consist of a remote code execution flaw and an access control bypass issue that, when chained together, allow remote attackers to execute arbitrary code or cause denial-of-service conditions. Active exploitation has been confirmed in the wild.

On April 23, 2026, Cisco disclosed that compromised devices may have persistent malicious functionality embedded, allowing attackers to maintain access even after patching. This indicates that victims cannot simply remediate by applying updates — full device reconstruction may be necessary for previously compromised systems. The persistent nature of the compromise represents a significant escalation in the threat landscape for perimeter security devices.

IPA strongly recommends immediate patching to the latest versions provided by Cisco. Organizations that suspect prior compromise should consult Cisco's IOC information and follow their guidance on device rebuild procedures to ensure complete remediation.

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20251106.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free